From privacy promises to privacy management: a new approach for enforcing privacy throughout an enterprise

  • Authors:
  • Paul Ashley;Calvin Powers;Matthias Schunter

  • Affiliations:
  • IBM Software Group, Gold Coast, Australia;IBM Software Group, Raleigh, NC;IBM Research, Zurich, Switzerland

  • Venue:
  • Proceedings of the 2002 workshop on New security paradigms
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Regulations and consumer backlash force many organizations to re-evaluate the way they manage private data. As a first step, they publish privacy promises as text or P3P. These promises are not backed up by privacy technology that enforces the promises throughout the enterprise. Privacy tools cover fractions of the problem while leaving the main challenge unanswered.This article describes a new approach towards enterprise-wide enforcement of the privacy promises. Its core is a new framework for managing collected personal data in a sensitive, trustworthy way. The framework enables enterprises to publish clear privacy promises, to collect and manage user preferences and consent, and to enforce the privacy promises throughout the enterprise.One of the foundations of this framework is the "sticky policy paradigm" that defines a customer centric model for managing policies, preferences, and consent.