A systematic approach to privacy enforcement and policy compliance checking in enterprises

  • Authors:
  • Marco Casassa Mont;Siani Pearson;Robert Thyne

  • Affiliations:
  • Hewlett-Packard Labs, Trusted Systems Lab, Bristol, UK;Hewlett-Packard Labs, Trusted Systems Lab, Bristol, UK;Hewlett-Packard, Software Business Organisation, Toronto, Canada

  • Venue:
  • TrustBus'06 Proceedings of the Third international conference on Trust, Privacy, and Security in Digital Business
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Privacy management is important for enterprises that handle personal data: they must deal with privacy laws and people’s expectations. Currently much is done by means of manual processes, which make them difficult and expensive to comply. Key enterprises’ requirements include: automation, simplification, cost reduction and leveraging of current identity management solutions. This paper describes a suite of privacy technologies that have been developed by HP Labs, in an integrated way, to help enterprises to automate the management and enforcement of privacy policies (including privacy obligations) and the process of checking that such policies and legislation are indeed complied with. Working prototypes have been implemented to demonstrate the feasibility of our approach. In particular, as a proof-of-concept, the enforcement of privacy policies and obligations has been integrated with HP identity management solutions. Part of this technology is currently under productisation. Technical details are provided along with a description of our next steps.