论文标题

了解数据隐私合规过程中技术措施的实施:一项定性研究

Understanding the Implementation of Technical Measures in the Process of Data Privacy Compliance: A Qualitative Study

论文作者

Klymenko, Oleksandra, Kosenkov, Oleksandr, Meisenbacher, Stephen, Elahidoost, Parisa, Mendez, Daniel, Matthes, Florian

论文摘要

现代隐私法规,例如《通用数据保护法规》(GDPR),通过提及一般的“技术措施”以符合数据隐私合规性,而不是指示应如何实施这些隐私,以技术上不可知的方式解决软件系统中的隐私。但是,由于其跨学科的性质和必要的技术 - 法律互动,对技术措施的概念以及如何在实践中确切处理的理解并不是微不足道的。我们旨在调查如何在实践中了解数据隐私合规性的概念以及实施这些技术措施的过程中的技术 - 法律互动。我们遵循一种研究设计,即1)本质上的探索性,2)定性,以及3)基于面试的研究设计,在技术和法律领域中有16位选定的隐私专业人员。我们的结果表明,没有明确的相互理解,也没有公认的处理技术措施的方法。技术和法律角色都参与了此类措施的实施。尽管他们仍然经常在单独的领域中运作,但受访者中的主要意见是促进更多的跨学科合作。我们的经验发现证实,在实施数据隐私技术措施时,有必要在法律和工程团队之间进行更好的互动。我们认为,跨学科的合作对于对技术措施的更完整的了解至关重要,技术措施目前缺乏相互接受的概念。但是,正如我们的结果强烈建议的那样,这种相互作用仍然缺乏系统的方法。因此,结果增强了我们对需要进一步研究数据隐私合规技术动态的需求的信心。

Modern privacy regulations, such as the General Data Protection Regulation (GDPR), address privacy in software systems in a technologically agnostic way by mentioning general "technical measures" for data privacy compliance rather than dictating how these should be implemented. An understanding of the concept of technical measures and how exactly these can be handled in practice, however, is not trivial due to its interdisciplinary nature and the necessary technical-legal interactions. We aim to investigate how the concept of technical measures for data privacy compliance is understood in practice as well as the technical-legal interaction intrinsic to the process of implementing those technical measures. We follow a research design that is 1) exploratory in nature, 2) qualitative, and 3) interview-based, with 16 selected privacy professionals in the technical and legal domains. Our results suggest that there is no clear mutual understanding and commonly accepted approach to handling technical measures. Both technical and legal roles are involved in the implementation of such measures. While they still often operate in separate spheres, a predominant opinion amongst the interviewees is to promote more interdisciplinary collaboration. Our empirical findings confirm the need for better interaction between legal and engineering teams when implementing technical measures for data privacy. We posit that interdisciplinary collaboration is paramount to a more complete understanding of technical measures, which currently lacks a mutually accepted notion. Yet, as strongly suggested by our results, there is still a lack of systematic approaches to such interaction. Therefore, the results strengthen our confidence in the need for further investigations into the technical-legal dynamic of data privacy compliance.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源