Privacy Policy Compliance for Web Services

  • Authors:
  • George Yee;Larry Korba

  • Affiliations:
  • National Research Council Canada;National Research Council Canada

  • Venue:
  • ICWS '04 Proceedings of the IEEE International Conference on Web Services
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

The growth of the Internet has been accompanied bythe growth of web services (e.g. e-commerce, e-health).This proliferation of web services and theincreasing regulatory and legal requirements forpersonal privacy have fueled the need to protect thepersonal privacy of web service users. We advocate aprivacy policy negotiation approach to protectingpersonal privacy [Bilateral E-services Negotiation Under Uncertainty, The Negotiation of Privacy Policies in Distance Education]. We provided semi-automatedapproaches for deriving personal privacy policies in[Semi-Automated Derivation of Personal Privacy Policies]. However, it is evident that approaches are also needed to ensure that providers of web servicescomply with the privacy policies of service users. Inthis paper, we examine privacy legislation to deriverequirements for privacy policy compliance systems.We then propose an architecture for a privacy policycompliance system that satisfies the requirements anddiscuss the strengths and weaknesses of our proposedarchitecture.