Translating Privacy Practices into Privacy Promises—How to Promise What You Can Keep

  • Authors:
  • Günter Karjoth;Matthias Schunter;Els Van Herreweghen

  • Affiliations:
  • -;-;-

  • Venue:
  • POLICY '03 Proceedings of the 4th IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

Enterprises advertise privacy promises using the W3CPlatform for Privacy Preferences (P3P). These privacypromises define what recipients can obtain what collecteddata for what purpose. Internally, enterprises can use fine-grainedprivacy practices such as defined by the Platformfor Enterprise Privacy Practices (E-P3P) to enforce privacy.These internal privacy policies should guarantee andenforce the promises made to the customers. Since privacypractices reflect business internals, they can changefrequently. As a consequence, it can be challenging to keepthe promises up-to-date with the actual practices. To enableup-to-date privacy promises, we describe a methodology forenterprises to promise what they can keep. This is doneby automatically transforming E-P3P privacy practices intocorresponding P3P privacy promises that reflect the actualenterprise-internal behavior. These P3P promises can thenbe published on a regular basis. Whenever the internalpolicies change, the P3P promises can easily be updatedas well.