Enhancing user privacy through data handling policies

  • Authors:
  • C. A. Ardagna;S. De Capitani di Vimercati;P. Samarati

  • Affiliations:
  • Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, Crema, Italy;Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, Crema, Italy;Dipartimento di Tecnologie dell'Informazione, Università degli Studi di Milano, Crema, Italy

  • Venue:
  • DBSEC'06 Proceedings of the 20th IFIP WG 11.3 working conference on Data and Applications Security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

The protection of privacy is an increasing concern in today's global infrastructure. One of the most important privacy protection principles states that personal information collected for one purpose may not be used for any other purpose without the specific informed consent of the person it concerns. Although users provide personal information for use in one specific context, they often have no idea on how such a personal information may be used subsequently. In this paper, we introduce a new type of privacy policy, called data handling policy, which defines how the personal information release will be (or should be) dealt with at the receiving party. A data handling policy allows users to define simple and appropriate levels of control over who sees what information about them and under which circumstances.