Title
Towards scalable management of privacy obligations in enterprises
Abstract
Privacy management is important for enterprises that collect, store, access and disclose personal data. Among other things, the management of privacy includes dealing with privacy obligations that dictate duties and expectations an enterprise has to comply with, in terms of data retention, deletion, notice requirements, etc. This is still a green area open to research and innovation: it is about enabling privacy-aware information lifecycle management. This paper provides an overview of the work we have done in this space: definition of an obligation management model and a related framework; implementation of a prototype of an obligation management system integrated both in the context of the PRIME project and with an HP identity management solution. This paper then focuses on an important open issue: how to make our approach scalable, in case large amounts of personal data have to be managed. Thanks to our integration work and the feedback we received, we learnt more about how users and enterprises are likely to deal with privacy obligations. We describe these findings and how to leverage them. Specifically, in the final part of this paper we introduce and discuss the concepts of parametric obligation and “hybrid” obligation management and how this can improve the scalability and flexibility of our system. Our work is in progress. Further research and development is going to be done in the context of the PRIME project and an HP Labs project.
Year
DOI
Venue
2006
10.1007/11824633_1
TrustBus
Keywords
Field
DocType
obligation management model,prime project,parametric obligation,personal data,obligation management system,hp identity management solution,privacy-aware information lifecycle management,towards scalable management,privacy obligation,privacy management,obligation management,management system,identity management
Information system,Information management,Obligation,Data retention,Computer security,Computer science,Information technology,Identity management,Notice,Management system
Conference
Volume
ISSN
ISBN
4083
0302-9743
3-540-37750-6
Citations 
PageRank 
References 
7
0.88
3
Authors
1
Name
Order
Citations
PageRank
Marco Casassa Mont128933.03