论文标题
从Web服务中提取分层隐私语言目的
Extracting Layered Privacy Language Purposes from Web Services
论文作者
论文摘要
Web服务对于在万维网中处理个人数据很重要。鉴于最近的数据保护法规,这种处理提出了有关法律处理的同意或其他基础的问题。尽管必须告知同意书,但许多Web服务无法提供足够的信息供用户做出明智的决定。隐私政策和隐私语言是解决此问题的一种方法;前者文档如何处理个人数据,而后者则正式描述了此处理。在本文中,Sopalled分层隐私语言(LPL)与Web服务相结合,以用正式的分析方法表达个人数据处理,该方法旨在为隐私政策生成处理目的。为此,本文回顾了背景理论,并提出了一种方法和一种具体工具。通过小案例研究证明了结果。
Web services are important in the processing of personal data in the World Wide Web. In light of recent data protection regulations, this processing raises a question about consent or other basis of legal processing. While a consent must be informed, many web services fail to provide enough information for users to make informed decisions. Privacy policies and privacy languages are one way for addressing this problem; the former document how personal data is processed, while the latter describe this processing formally. In this paper, the socalled Layered Privacy Language (LPL) is coupled with web services in order to express personal data processing with a formal analysis method that seeks to generate the processing purposes for privacy policies. To this end, the paper reviews the background theory as well as proposes a method and a concrete tool. The results are demonstrated with a small case study.