Purpose control: did you process the data for the intended purpose?

  • Authors:
  • Milan Petković;Davide Prandi;Nicola Zannone

  • Affiliations:
  • Philips Research Eindhoven and Eindhoven University of Technology;Centre for Integrative Biology, University of Trento;Eindhoven University of Technology

  • Venue:
  • SDM'11 Proceedings of the 8th VLDB international conference on Secure data management
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

Data protection legislation requires personal data to be collected and processed only for lawful and legitimate purposes. Unfortunately, existing protection mechanisms are not appropriate for purpose control: they only prevent unauthorized actions from occurring and do not guarantee that the data are actually used for the intended purpose. In this paper, we present a flexible framework for purpose control, which connects the intended purpose of data to the business model of an organization and detects privacy infringements by determining whether the data have been processed only for the intended purpose.