Implementing Privacy by Design through Privacy Impact Assessments

dc.contributor.authorFoujdar, Ameya
dc.contributor.departmentfi=Oikeustieteellinen tiedekunta|en=Faculty of Law|
dc.contributor.facultyfi=Oikeustieteellinen tiedekunta|en=Faculty of Law|
dc.contributor.studysubjectfi=Oikeustiede, OTM-tutkinto|en=Law, Master of Laws|
dc.date.accessioned2019-06-10T21:01:04Z
dc.date.available2019-06-10T21:01:04Z
dc.date.issued2019-05-22
dc.description.abstractPrivacy has come a long way from being a fundamental physical right to being implemented as virtual online privacy under GDPR. Recent privacy breaches around the world have highlighted the role of the design of information systems in protecting the privacy of individuals online. GDPR envisions to achieve this through Privacy by Design (PbD) in business and technological systems. Privacy by Design is the law regulating the architecture of information systems through its code and organizational measures to facilitate usercentric privacy. It is relatively a new concept initially developed by Ann Cavoukian along with PbD Principles. The principles themselves do not ensure the holistic implementation of the PbD process. What is lacking in the current model of PbD is an implementation mechanism to operationalize the PbD as a process. This study builds upon the model suggested by Kroener and Wright to operationalize PbD through a dual approach: a set of principles (PbD Principles) and a process (PIAs). Firstly, this study starts an informed discussion on PbD and its robust theoretical basis under Lessig's Theory of Regulation. Secondly, it proposes to address the lack of operationalization by using Privacy Impact Assessments (PIAs) as a tool to conduct the PbD process. It brings together the two concepts and shows how PbD, as a process, can be better performed if complemented with PIAs. Lastly, it develops a framework for such a PbD process and constructs a lifecycle model to address the gaps in its operationalization. It demonstrates the feasibility of the developed PbD operationalization model by applying it to an existing information system: the Föli Mobile Application.
dc.format.extent82
dc.identifier.olddbid164685
dc.identifier.oldhandle10024/147844
dc.identifier.urihttps://www.utupub.fi/handle/11111/12340
dc.identifier.urnURN:NBN:fi-fe2019061019771
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.source.identifierhttps://www.utupub.fi/handle/10024/147844
dc.subjectPrivacy by Design, Information systems, Privacy Impact Assessments, personal information, privacy regulation
dc.titleImplementing Privacy by Design through Privacy Impact Assessments
dc.type.ontasotfi=Pro gradu -tutkielma|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Foujdar_Ameya_Thesis.pdf
Size:
1.67 MB
Format:
Adobe Portable Document Format